isc.sans.edu 5 Oct 2026, 02:00 UTC

FortiMail Flaw Exploited to Enable Unauthenticated Remote Code Execution

FortiMail Flaw Exploited to Enable Unauthenticated Remote Code Execution

THE SANS ISC podcast for 5 October 2026 rounds up ongoing internet scanning activity via honeypots, noting that many scans carry spoofed or misleading user agent strings. They point out that while some strings come from researchers or security vendors, attackers will not use legitimate-looking agents; blocking certain user agents can reduce noise and help lessen load on web apps.

The discussion also mentions that some strings originate from companies scanning the internet for their own purposes, and over time the ISC team tracks dozens of organisations behind such scans.

On the vulnerability front, Fortinet released an update for FortiMail that addresses a path traversal flaw exploited prior to patch. The issue involves the null byte character, and, when exploited, can allow an unauthenticated attacker to write arbitrary files on the underlying system, enabling remote code execution. Fortinet notes this vulnerability is linked to the identity-based encryption (IBE) feature in FortiMail; they suggest, if the feature is not in use, turning it off as a precaution.

Fortinet also provides indicators of compromise to help defenders spot exploitation in logs. Separately, for GitLab on‑premises deployments, there is a critical update for the AI gateway that can let an attacker manipulate workflows and potentially achieve code execution, though this is an issue only for on‑premise installations; GitLab’s cloud deployments are already patched.

The broadcast also touches on macOS changes: Apple is tightening how applications obtain file-system access, with a move towards more granular permission controls and away from full disk access, citing risks to user data and to communications data as part of future changes.

View full article

Article by CyberSIXT